Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2023-40809
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
Opencrx
No fix yet
CRITICAL 9.8
CVE-2023-6188
A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin…
Getsimplecms
No fix yet
CRITICAL 9.8
CVE-2023-6016EPSS 31%
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
H2o
No fix yet
CRITICAL 9.8
CVE-2023-47003
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD…
Redisgraph
No fix yet
HIGH 8.8
CVE-2023-47444
An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untr…
Opencart
after 4.0.2.3
HIGH 8.8
CVE-2023-48217
Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…
Statamic
3.4.14 / 4.34.0+
HIGH 8.8
CVE-2023-36437
Azure DevOps Server Remote Code Execution Vulnerability
Azure Pipelines Agent
2.39.1+
HIGH 8.8
CVE-2023-6131
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
HIGH 8.8
CVE-2023-6125
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
CRITICAL 9.8
CVE-2023-6126
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
HIGH 7.5
CVE-2023-45560
An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
Memberscard
No fix yet
HIGH 7.3
CVE-2023-36014
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
119.0.2151.58+
CRITICAL 9.8
CVE-2023-5550
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the …
Moodle
3.9.24 / 3.11.17+
HIGH 8.8
CVE-2023-5540
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Moodle
3.9.24 / 3.11.17+
HIGH 8.8
CVE-2023-5539
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
Moodle
3.9.24 / 3.11.17+
CRITICAL 9.8
CVE-2023-47397
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
Webid
after 1.2.2
CRITICAL 9.8
CVE-2023-45849
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
Helix Core
2023.2+
HIGH 8.8
CVE-2023-46243
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a use…
Xwiki
14.10.6 / 15.2+
HIGH 8.8
CVE-2023-46242
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execut…
Xwiki
14.10.7 / 15.2+
HIGH 7.2
CVE-2023-46845
EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vul…
Ec Cube
4.2.3+
CRITICAL 9.8
CVE-2023-46731EPSS 89%
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section UR…
Xwiki
14.10.14 / 15.5.1+
CRITICAL 9.9
CVE-2023-46404
PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.
Pcrs
after 3.11
CRITICAL 9.8
CVE-2023-46980
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to t…
Best Courier Management System
No fix yet
HIGH 8.8
CVE-2023-46947
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
Subrion
No fix yet
MEDIUM 6.6
CVE-2023-36022
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
118.0.2088.88 / 119.0.2151.44+
CRITICAL 9.8
CVE-2023-46958
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
Lmxcms
Mitigation only
HIGH 8.2
CVE-2023-20063
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devic…
Secure Firewall Management Center
after 7.3.1.1
HIGH 8.8
CVE-2023-40050
Upload profile either
through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
check command with malicious…
Automate
after 4.10.29
HIGH 7.8
CVE-2023-42658
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
Inspec
4.56.58 / 5.22.29+
CRITICAL 9.8
CVE-2023-43792
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. A…
Basercms
after 4.7.6